2025 CVE Vulnerabilities

45,194 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66020HIGH7.5Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i...
CVE-2025-12848MEDIUM6.1Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name ...
CVE-2025-66265MEDIUM6.9CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a...
CVE-2025-66264HIGH7.2The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacke...
CVE-2025-66263HIGH7.5Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66262CRITICAL9.8Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit...
CVE-2025-66261CRITICAL9.8Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66260MEDIUM6.5PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, ...
CVE-2025-66259CRITICAL9.8Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mo...
CVE-2025-66258MEDIUM5.4Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions ...
CVE-2025-66257CRITICAL9.1Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm...
CVE-2025-66256CRITICAL9.8Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit...
CVE-2025-66255CRITICAL9.8Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm...
CVE-2025-66254CRITICAL9.1Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Tran...
CVE-2025-66253CRITICAL9.8Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte...
CVE-2025-66252HIGH7.5Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte...
CVE-2025-66251CRITICAL9.1Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66250CRITICAL9.8Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-64657CRITICAL9.8Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a ne...
CVE-2025-64656CRITICAL9.8Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-66019MEDIUM6.6pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability...
CVE-2025-65963MEDIUM5.4Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient...
CVE-2025-65957HIGH8.8Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_...
CVE-2025-65956MEDIUM5.4Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into t...
CVE-2025-65953MEDIUM6NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now